Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Poland says fire at Starlink station is sabotage as Denmark warns of rising Russian threat

    September 24, 2026

    EU launches diplomatic offensive to stop Trump’s diesel export ban – POLITICO

    September 24, 2026

    The Inquiry – How did Italian politics become stable?

    September 24, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Poland says fire at Starlink station is sabotage as Denmark warns of rising Russian threat
    • EU launches diplomatic offensive to stop Trump’s diesel export ban – POLITICO
    • The Inquiry – How did Italian politics become stable?
    • Bose Ultra Open Earbuds Are $100 Off Right Now
    • CISA: Ransomware gangs now exploiting critical TeamCity flaw
    • Cosmos restarted to seize $2.2 million in stolen ATOM, but 169,000 tokens still escaped
    • Elephants treat themselves with medicinal plants, witnesses say
    • Fat Bear Week opens for Alaska’s heavyweight crown. Can Chunk, the 1,200-pound champ, win again?
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, September 24
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 9, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananAug 07, 2026Cybercrime / Vulnerability

    A new analysis has uncovered that the threat actor tracked as TeamPCP has been active on the cybercrime scene as far back as 2020, indicating the group has been compromising internet-facing infrastructure for years before training their sights on the software supply chain.

    “The connection is supported by overlapping domains, malware deployment paths, staging techniques, backend infrastructure, and operational tradecraft,” Oligo Security researchers Avi Lumelsky and Gal Elbaz said.

    This includes two campaigns observed in the second half of 2025: ShadowRay 2.0 (aka IronErn), which involved hijacking artificial intelligence (AI) infrastructure into a self-propagating botnet, and TA-NATALSTATUS, which targeted exposed Redis servers to deliver cryptocurrency miners.

    TA-NATALSTATUS is assessed to be an evolution of a prior campaign that was detailed by Trend Micro in April 2020 that involved targeting Redis servers to deploy malware. This suggests that the threat actor has been actively targeting internet-accessible infrastructure across Ray, Docker, Redis, and React much before it branded itself as TeamPCP.

    Cybersecurity

    Details of the attackers first emerged towards the end of last year when they were linked to the exploitation of security flaws in React Server Components (RSC) and Next.js to facilitate the extraction of credentials and sensitive data from compromised environments. The activity was codenamed Operation PCPcat.

    Then, earlier this year, Flare detailed a massive campaign undertaken by the threat actor to systematically target cloud native environments as part of efforts to set up malicious infrastructure for follow-on exploitation.

    “The operation’s goals were to build a distributed proxy and scanning infrastructure at scale, then compromise servers to exfiltrate data, deploy ransomware, conduct extortion, and mine cryptocurrency,” Flare security researcher Assaf Morag noted at the time.

    The group has since branched into high-profile supply chain compromises, weaponizing the interconnected nature of modern software to infect developer systems en masse by poisoning popular open-source libraries through a combination of GitHub Actions and token theft abuse.

    “One of the strongest operational links is the overlap between the IronErn GitHub and GitLab identities observed during ShadowRay 2.0 and TeamPCP’s later infrastructure,” Oligo said. “Correlating GitLab authentication logs, command-and-control infrastructure, reverse-shell activity, and malware staging establishes a direct operational bridge between the ShadowRay 2.0 campaign and the actor later operating publicly as TeamPCP.”

    The latest findings show that not only are these efforts linked, but also that the threat actor repeatedly abused known security flaws impacting React, Docker, Redis, and Ray to gain access and rely on automated and wormable exploitation techniques for self-propagation.

    Cybersecurity

    The expansion into cascading software supply chain attacks, therefore, represents a natural evolution of this trend, allowing the threat actors to take advantage of legitimate cloud infrastructure and repurpose tried and tested methods in their efforts.

    These shifts have been complemented by continuous updates to its malware arsenal, including a Python script (“kube.py”) that’s specifically used after breaching Kubernetes environments. While earlier versions of the script focused on propagation and setting up persistence, new variants observed as recently as March 2026 began to incorporate wiper-like functionality.

    This destructive code path checked whether the victim system was configured for the Iran timezone and, if that’s the case, fired a DaemonSet that wiped every node in the cluster via a wiper not-so-subtly named Kamikaze. On Kubernetes nodes located outside of Iran, it deployed the CanisterWorm backdoor. For non-Kubernetes Iranian systems, the malware executed a “poison_pill()” routine to erase the entire file system.

    “Whether this continuity reflects a direct rebrand, a shared operator set, or close collaboration between historically related actors cannot be determined with 100% certainty,” Oligo said. “What the evidence does demonstrate is that TeamPCP represents the continuation of an existing operational ecosystem rather than an entirely new threat actor that appeared in late 2025.”

    attacks campaign chain Dating linked Redis supply TeamPCP
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    CISA: Ransomware gangs now exploiting critical TeamCity flaw

    OT Security Guidance: NIST Drafts Updated Guide, CISA/FBI Advise on ICS Integrators

    OpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Public Files

    58 hardware vulnerabilities: A guide to the threats

    Critical WordPress Vulnerability Exploited Immediately After Disclosure

    Hackers start exploiting critical WordPress flaw for code execution

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Poland says fire at Starlink station is sabotage as Denmark warns of rising Russian threat

    September 24, 2026

    EU launches diplomatic offensive to stop Trump’s diesel export ban – POLITICO

    September 24, 2026

    The Inquiry – How did Italian politics become stable?

    September 24, 2026

    Bose Ultra Open Earbuds Are $100 Off Right Now

    September 24, 2026
    Latest Posts

    Ransom Cartel ransomware creator sentenced to 16 years in prison

    August 5, 2026

    Uber CEO brushes off reports of a Waymo break-up

    August 5, 2026

    Fauci Faces Contempt Vote. Here Are the Legal Issues Involved.

    August 6, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Poland says fire at Starlink station is sabotage as Denmark warns of rising Russian threat

    September 24, 2026

    EU launches diplomatic offensive to stop Trump’s diesel export ban – POLITICO

    September 24, 2026

    The Inquiry – How did Italian politics become stable?

    September 24, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.